<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: it is possible that logs get duplicated between , Splunk enterprise and Splunk enterprise security? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626948#M11253</link>
    <description>&lt;P&gt;I'm not sure I understand the question.&amp;nbsp; Data not ingested is not counted and does not apply to your license quota.&lt;/P&gt;&lt;P&gt;What do you mean by "how does it measure"?&amp;nbsp; What is "it"?&lt;/P&gt;&lt;P&gt;Please understand that Enterprise Security searches and visualizes data (along with other UI features).&amp;nbsp; It does not onboard/ingest data and does not measure license volume.&amp;nbsp; Those tasks are handled by Splunk Enterprise, the foundation for ES.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jan 2023 16:23:58 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-01-12T16:23:58Z</dc:date>
    <item>
      <title>Is it possible that logs get duplicated between Splunk Enterprise and Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626925#M11250</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;I want to know if is possible to get duplicated ingestion of logs between Splunk Enterprise and Splunk enterprise security,&amp;nbsp; also the availability of the logs of Splunk enterprise in searches made on Splunk Enterprise security. and in general how this work on an indexer level.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 18:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626925#M11250</guid>
      <dc:creator>Matilda</dc:creator>
      <dc:date>2023-01-12T18:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: it is possible that logs get duplicated between , Splunk enterprise and Splunk enterprise security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626932#M11251</link>
      <description>&lt;P&gt;Splunk Enterprise Security does not ingest data.&amp;nbsp; It merely works with data ingested by Splunk Enterprise using technology add-ons (TAs).&amp;nbsp; So, no, ES is not duplicating ingestion of your logs.&amp;nbsp; It is possible, however, for a search to produce results that might look like duplicated ingestion.&amp;nbsp; Also, this does not mean you are experiencing duplicate ingestion - it merely means it's not ES's fault.&lt;/P&gt;&lt;P&gt;Access to indexes by ES is controlled by RBAC exactly the way it is done in Splunk Enterprise.&amp;nbsp; That's because ES is simply an app that plugs into Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 14:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626932#M11251</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-12T14:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: it is possible that logs get duplicated between , Splunk enterprise and Splunk enterprise security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626935#M11252</link>
      <description>&lt;P&gt;hi, first o fall thank you... but how does it measure the volume if do not ingest? to my knowledge, we have to pay for volume. I am so sorry I bother you again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 14:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626935#M11252</guid>
      <dc:creator>Matilda</dc:creator>
      <dc:date>2023-01-12T14:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: it is possible that logs get duplicated between , Splunk enterprise and Splunk enterprise security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626948#M11253</link>
      <description>&lt;P&gt;I'm not sure I understand the question.&amp;nbsp; Data not ingested is not counted and does not apply to your license quota.&lt;/P&gt;&lt;P&gt;What do you mean by "how does it measure"?&amp;nbsp; What is "it"?&lt;/P&gt;&lt;P&gt;Please understand that Enterprise Security searches and visualizes data (along with other UI features).&amp;nbsp; It does not onboard/ingest data and does not measure license volume.&amp;nbsp; Those tasks are handled by Splunk Enterprise, the foundation for ES.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 16:23:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626948#M11253</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-12T16:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: it is possible that logs get duplicated between , Splunk enterprise and Splunk enterprise security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626965#M11254</link>
      <description>&lt;P&gt;Enterprise Security does not measure anything. It's licensed based on your "main" license ingestion limit. There is no possiblity to have - for example - a Splunk Enterprise license for 50GB daily ingestion volume and Enterprise Security License for 15GB. If you have a license for Splunk Enterprise for 50GB, you must buy a ES license for 50GB as well.&lt;/P&gt;&lt;P&gt;If you exceed your daily ingestion, normal Splunk Enterprise mechanisms kick in.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 18:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Is-it-possible-that-logs-get-duplicated-between-Splunk/m-p/626965#M11254</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-12T18:45:17Z</dc:date>
    </item>
  </channel>
</rss>

